Cloud Security Engineer
Security engineer job in Philadelphia, PA
Apply now: Cloud Security Engineer (Principal InfoSec Specialist), location is Hybrid (Philadelphia, PA). The start date is 12/22/25 for this contract-to-hire position.
Job Title: Cloud Security Engineer (Principal InfoSec Specialist)
Location-Type: Hybrid (80% remote, 20% onsite - Philadelphia, PA)
Start Date Is: 12/22/25
Duration: 6-month contract-to-hire
Compensation Range: $80-102/hr on W2 ONLY
Job Description:
Serve as a subject matter expert for cloud security architecture and controls, driving risk-based outcomes and optimizing cloud security operations in a hybrid multi-cloud environment.
Day-to-Day Responsibilities:
Design, implement, and optimize cloud security controls and tools
Support cloud migration and secure cloud services delivery
Collaborate across internal teams and vendors on security architecture
Manage security tools like EDR, SIEM, IAM, CSPM
Lead or support incident response, system hardening, and compliance activities
Participate in audits, risk assessments, and governance forums
Mentor junior InfoSec engineers
Ensure alignment with industry standards and compliance frameworks
Requirements:
Must-Haves:
Bachelor's Degree
12+ years of IT experience, with 6+ years in InfoSec and 3+ years in IAM, RBAC, or related areas
Strong experience with cloud/virtualization technologies (Azure preferred)
Experience with multi-cloud security, identity management, and regulatory compliance
Proficiency in tools like Microsoft Defender, Sentinel/Splunk, Wiz, Entra ID, Terraform
CISSP certification
Nice-to-Haves:
Cloud security certifications (e.g., Azure Security Engineer, AWS Certified Security)
Experience working with high-performance matrixed teams
Familiarity with clinical systems (e.g., Epic, Lawson) and SDLC methodologies
Benefits:
This role is eligible to enroll in both Mondo's health insurance plan and retirement plan. Mondo defers to the applicable State or local law for paid sick leave eligibility
Cloud Security Engineer
Security engineer job in Philadelphia, PA
Our client is one of the largest Hospitals in the US. Based out of Philadelphia, they are looking to hire a Cloud Security Engineer on a Contract basis.
Contract Duration: 6 Month Contract (Potential for extension or conversion)
Required Skills & Experience
At least twelve (12) years industry related experience, including experience in one to two IT disciplines (such as technical architecture, network management, application development, middleware, information analysis, database management or operations) in a multitier environment.
CISSP Certification
At least six (6) years experience with information security, regulatory compliance and risk management concepts.
At least three (3) years experience with Identity and Access Management, user provisioning, Role Based Access Control, or control self-assessment methodologies and security awareness training.
Experience with Cloud and/or Virtualization technologies.
Demonstrates comprehensive knowledge and understanding of Information security principles, general and IT controls (e.g., access controls, risk management, change management, cloud security) and related information security policies and procedures.
Exhibits knowledge of industry regulatory standards and accreditation requirements or control frameworks (HIPAA, PCI, Joint Commission, NIST, Red Flags, ISO 27000 series).
Comprehensive knowledge of information security regulations, standards and leading practices, including understanding of EHR, cloud frameworks, identity access controls.
Good knowledge of basic database query techniques & data mining to analyze data or other related database functionality.
Knowledge of Microsoft Active Directory, UNIX, and Clinical Applications a plus.
Experience implementing application level security in clinical and financial systems (e.g., Epic, Lawson). ERP experience a plus.
General understanding of networking and communication techniques including WANs, LANs, Internet, Intranet, protocols, such as TCP/IP and their impact on security.
Microsoft, UNIX, Lawson, and Clinical Applications,
Experience with industry standard SDLC methodologies; hands-on experience in Project Server methodologies, PMO project management skills, including use of MS productivity tools (Access, Word, PowerPoint, Visio, Project).
Experience with risk management frameworks.
Information Security Requirements
Understand and comply with all enterprise and IS departmental information security policies, procedures and standards.
Support the integration of information security in the development, design, and implementation of Hospital Technology Resources that process, transmit, or store information.
Support all compliance activities related to state, federal regulatory requirements, healthcare accreditation standards, and all other applicable regulations that govern the use and disclosure of patient, financial, or other confidential information.
Daily Responsibilities
Optimizes information management approaches through an understanding of evolving business needs and technology capabilities and ensures that projects do not duplicate functionality or diverge from each other and business and DTS strategies.
Shapes, designs, and plans specific service lines in product area and manages the risks associated with information and DTS assets through appropriate standards and security policies.
Functions as the Subject Matter Expert (SME) to maintain an understanding of DTS business and clinical applications and the relationship to InfoSec and compliance solutions; assist Hospital stakeholders in understanding information protection needs that support the Hospital's business.
Works with other architects to provide a consensus based enterprise solution that is scalable, adaptable and in synchronization with ever changing business needs and takes ownership of a particular solution offering.
Works with highly matrixed team of DTS personnel to support enterprise architecture and information security operations including, but not limited to, architecture and InfoSec principles around identity & access management models, cloud identify management providers, security information and event monitoring, and data loss prevention, perimeter (e.g. firewalls, IPS, web filtering), cloud and virtualization environments and network security (host-based firewalls, anti-virus, disk encryption).
Support and/or lead activities around InfoSec standards for business continuity and change management activities (e.g., table tops and change review board) and educates DTS Hospital management on security issues (e.g., Identity and Access Management (IAM), Role Based Access Control (RBAC) models.
You will receive the following benefits:
Medical Insurance - Four medical plans to choose from for you and your family
Dental & Orthodontia Benefits
Vision Benefits
Health Savings Account (HSA)
Health and Dependent Care Flexible Spending Accounts
Voluntary Life Insurance, Long-Term & Short-Term Disability Insurance
Hospital Indemnity Insurance
401(k) including match with pre and post-tax options
Paid Sick Time Leave
Legal and Identity Protection Plans
Pre-tax Commuter Benefit
529 College Saver Plan
Motion Recruitment Partners (MRP) is an Equal Opportunity Employer. All applicants must be currently authorized to work on a full-time basis in the country for which they are applying, and no sponsorship is currently available. Employment is subject to the successful completion of a pre-employment screening. Accommodation will be provided in all parts of the hiring process as required under MRP's Employment Accommodation policy. Applicants need to make their needs known in advance.
Principal Cloud Security Engineer
Security engineer job in Philadelphia, PA
Title: Cloud Security Principal Engineer
Job Duration: 6 months (Contract to Hire)
We are seeking an experienced Cybersecurity Engineer to strengthen enterprise security across cloud and on-prem environments. This role focuses on enhancing identity, access, and threat protection capabilities while supporting automation, compliance, and continuous security improvement. The ideal candidate brings strong hands-on security engineering skills, deep Azure experience, and proven success designing and operating security controls within large, complex environments.
Responsibilities
Implement, configure, and maintain enterprise security tools including SIEM, EDR, IAM, and CSPM solutions
Engineer and operate security controls across Azure and hybrid environments
Lead IAM / RBAC / user access governance initiatives to improve authentication and authorization workflows
Monitor, investigate, and respond to security threats through SIEM and SOC processes
Drive automation of security and identity tasks using Terraform, PowerShell, and scripting
Collaborate with infrastructure, applications, and architecture teams to ensure secure design and deployment practices
Support vulnerability remediation, risk assessments, and compliance requirements
Contribute to security standards, documentation, and best practices for ongoing maturity and scalability
Required Qualifications
CISSP certification (mandatory)
12+ years overall IT experience across network, systems, and/or application platforms
6+ years in Cybersecurity with a focus on security engineering
3+ years in IAM / RBAC / identity governance
Strong hands-on knowledge of Azure Security, virtualization, and Microsoft security ecosystem
Experience with security monitoring and defense tools such as:
Microsoft Sentinel, Microsoft Defender, Splunk, Wiz (or similar)
Skilled in automation using Terraform, PowerShell, or equivalent scripting tools
Preferred Qualifications
Additional cloud security certifications (e.g., AZ-500, CCSP)
Experience supporting security in healthcare or regulated industries
Familiarity with DevSecOps practices and secure CI/CD integration
Work Environment
Hybrid: ~80% remote / 20% onsite each week
Location: Philadelphia Metro area
Contract-to-permanent conversion opportunity
Candidates must be willing to commute onsite as required
Why Join
Visible role influencing enterprise-wide security posture
Opportunity to work with modern security technologies in critical infrastructure
Long-term career potential through contract-to-hire pathway
Security Incident Response Engineer III
Security engineer job in Philadelphia, PA
Are you considering a new role in Cyber Security and want to work in a company that is helping to change the world? Consider joining an organization serving the global scientific research community, supporting the brightest minds on the planet.
Are you a collaborative Incident Response Engineer looking to work for a mission driven global organization?
About the role, Elsevier is expanding its Global InfoSec Security Incident Response team. As a Security Incident Response Engineer, you will play a crucial role in our internal security support team, assisting with incident response investigations.
This team is entrusted with analyzing, triaging, scoping, containing, and providing guidance for remediation, as well as determining the root cause of security incidents. This team also is empowered by collecting and analyzing security incident-related data to identify indicators of attack and compromise.
Responsibilities:
Assisting in scoping security incidents and identifying indicators of attack and compromise.
Analyzing incident data from threat analytics tools.
Communicating recommendations and guidance based on security incident analysis.
Coordinating responses to security incidents with other security and consulting teams.
Developing, documenting, and implementing runbooks, capabilities, and techniques for Incident Response.
Performing security triage and analysis on endpoint, server, and network infrastructure.
Conducting activities necessary for immediate containment and short-term resolution of incidents.
Maintaining current knowledge of the threat landscape, emerging security threats, and vulnerabilities.
Investigating the root cause of complex security incidents.
Maintaining a high level of confidentiality.
Requirements
Possess experience in cybersecurity incident response or related fields.
Proven ability to analyze, triage, scope, contain, and remediate security incidents.
Have current and extensive knowledge of security technologies, tools, and processes.
Experience with major cloud providers, including cloud security, networking, and multi-cloud or hybrid deployments.
Have current skills in automation using PowerShell, Python, Java, or similar languages.
Experience in Linux and/or Mac administration. Experience in Network Security Administration or Systems Administration.
Experience supporting large, complex, and geographically distributed enterprise environments.
Preferred certifications: CISSP, CISM, SANS, GIAC, ethical hacking/penetration tester, or security risk assessment.
Elsevier employs 10,000 people worldwide, including over 2,500 technologists. We have supported the work of our research and health partners for more than 140 years. Growing from our roots in publishing, we offer knowledge and valuable analytics that help our users make breakthroughs and drive societal progress.
Senior Network Security Architect_ Onsite
Security engineer job in King of Prussia, PA
King of Prussia, Pennsylvania
Contract
Required Skills and Experience:
-Experience: Minimum 12 years of professional experience in network architecture, with at least 7 years focused on large-scale data center planning and deployment.
- Expert-level proficiency in Palo Alto Prisma (Cloud, Access, etc.) for cloud-native security and firewall management.
- Extensive experience with Zscaler for cloud security, zero-trust access, and secure web gateways.
- Advanced knowledge of Cisco Identity Services Engine (ISE) for network access control, policy enforcement, and identity management.
- Strong expertise in Aruba ClearPass for NAC, guest access, and device profiling.
- Proven experience implementing SASE solutions for secure, scalable cloud connectivity.
- Hands-on experience designing and deploying networks in multi-cloud environments (AWS, Azure, GCP).
- Deep understanding of data center networking (e.g., spine-leaf, VXLAN, BGP, EVPN).
- Proficiency in creating comprehensive LLD and HLD documentation for network and security architectures.
- Familiarity with network automation tools (e.g., Ansible, Terraform) and scripting (e.g., Python).
- Demonstrated success leading large-scale network and security deployments, including Prisma, Zscaler, Cisco ISE, and ClearPass integrations.
- Exceptional verbal and written communication skills, with the ability to convey complex technical concepts to diverse audiences.
Certifications:
- Palo Alto Networks Certified Network Security Architect (PCNSA/PCNSE).
- Zscaler Certified Cloud Professional (ZCCP) or equivalent.
- Cisco CCIE Security or CCNP Security.
- Aruba Certified ClearPass Professional (ACCP).
- AWS Certified Solutions Architect, Microsoft Azure Solutions Architect, or Google Cloud Professional Cloud Architect.
Qualifications:
- Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience).
Information Security Specialist
Security engineer job in Horsham, PA
Delta Information Systems, Inc. is seeking a highly skilled Information Security Specialist to protect and secure critical systems, data, and intellectual property in a fast-paced Aerospace & Defense environment.
This role is responsible for implementing and managing security controls, ensuring compliance with strict regulatory requirements, and defending against advanced cyber threats. The ideal candidate will bring deep technical knowledge, strong problem-solving skills, and the ability to work across teams to maintain the confidentiality, integrity, and availability of sensitive information that supports our national security mission.
This is a fully onsite position located in Horsham, PA.
Key Responsibilities
Implement, monitor, and maintain security tools, including firewalls, intrusion detection/prevention systems, endpoint protection, and SIEM platforms.
Perform continuous monitoring, vulnerability assessments, penetration testing, and risk analysis of systems and networks.
Ensure compliance with DoD, NIST 800-171, CMMC, ITAR, DFARS, and other regulatory frameworks.
Champion the company's certification to CMMC Level 2.
Develop, document, and enforce cybersecurity policies, procedures, and incident response plans.
Support Government and customer security audits, preparing evidence and remediation plans as required.
Investigate and respond to cybersecurity incidents, performing root-cause analysis and recommending corrective actions.
Collaborate with IT, Engineering, Program Management, and Security teams to embed cybersecurity best practices into operations and product development.
Provide cybersecurity awareness training to employees with a focus on handling sensitive defense-related data.
Stay current on emerging cyber threats, nation-state tactics, and evolving compliance regulations impacting aerospace and defense.
Qualifications
Required:
Bachelor's degree in Information Security, Computer Science, or related field (or equivalent experience).
5+ years of experience in information security, IT security operations, or cybersecurity.
Strong knowledge of NIST 800-171, CMMC, and DFARS cybersecurity requirements.
Experience developing, implementing and achieving CMMC compliance.
Experience supporting DoD or government contracts with cybersecurity compliance needs.
Hands-on experience with security infrastructure: SIEM, IDS/IPS, endpoint security, and network monitoring tools.
Strong understanding of Windows, Linux, and cloud environments (Microsoft Office 365, Deltek Costpoint).
Excellent analytical, documentation, and communication skills.
U.S. Citizenship (required due to defense industry regulations).
Preferred:
Active security clearance (Secret or higher), or ability to obtain one.
Relevant certifications: CISSP, CISM, Security+, CEH, or GIAC.
Experience with RMF (Risk Management Framework) and STIG compliance.
Familiarity with secure software development, DevSecOps practices, or classified system security.
Compensation
Competitive salary
Outstanding benefits package
100% Paid Coverage for Medical, Dental, and Vision
401(k) Employer Match
Employee Stock Ownership Program (company funded)
Life Insurance (company funded)
Short-Term Disability (company funded)
Long-Term Disability (company funded)
Vacation & Sick
Holidays: 11 days
HealthCare FSA
Dependent Care FSA
What We Offer
Opportunities for training, certifications, and career growth.
A mission-driven culture where your work contributes to national security.
Exposure to advanced technologies and programs critical to the aerospace and defense sector.
About Delta Information Systems, Inc.
Delta Information Systems (DIS) is an industry-leading supplier of high-quality aerospace telemetry products for Flight Test, Missile Test, Range Safety, Launch Support and Satellite Command and Control applications. Their products address the complete telemetry chain from Data Acquisition, Storage, Transport and Distribution to Telemetry Processing and Display. DIS customers include all DoD entities, all Major Primes, Integrators, Gov Labs, Aircraft & Missile Manufacturers, & Launch Facilities.
In addition, Delta Information Systems (DIS) designs and develops sophisticated electronic equipment that is specifically designed to reliably operate in harsh environments. They deliver critical video communications capability for manned and unmanned Intelligence, Surveillance and Reconnaissance (ISR) programs.
Systems Engineer (MSP)
Security engineer job in Oreland, PA
Systems Engineer (MSP) - T3 Escalations + Projects
📍 Oreland, PA (hybrid)
💰 $80,000 - $105,000
🖥️ MSP Experience Required
Join a fast-growing IT services firm where you'll drive infrastructure + cloud deployments, handle advanced escalations, and build long-term client relationships. This role blends hands-on engineering, project delivery, and light technical account management - ideal for a tech who wants ownership, client visibility, and growth.
What You'll Do
Serve as the top technical escalation point for complex issues
Lead infrastructure, cloud, and security projects end-to-end
Support and configure Microsoft 365, Azure AD, Windows Server, Intune
Manage VMware/Hyper-V and networking (firewalls, VLANs, VPNs, routing)
Oversee and harden backup, DR & EDR/security platforms
Mentor junior engineers & help elevate the tech stack and processes
Work closely with leadership, clients, and internal engineering teams
What You Bring
3+ years in an MSP supporting multiple clients (must-have)
Microsoft 365 / Azure / AD / Intune
Windows Server 2016-2025
VMware / Hyper-V
Networking + firewalls
Datto / Veeam / similar
Benefits
Bi Annual Bonuses
Medical, dental, vision
401(k)
PTO + holidays
Certification support & growth opportunities
Work in a tight-knit team where your voice matters
Microsoft 365 Security Engineer
Security engineer job in Philadelphia, PA
CompanyFederal Reserve Bank of PhiladelphiaThe Federal Reserve Bank of Philadelphia is one of the 12 regional Reserve Banks that, together with the Board of Governors in Washington, D.C., make up the Federal Reserve System. It helps formulate and implement monetary policy, supervises banks and bank and savings and loan holding companies, and provides financial services to depository institutions and the federal government. The Federal Reserve Bank of Philadelphia serves eastern and central Pennsylvania, southern New Jersey, and Delaware.
When you join the Federal Reserve-the nation's central bank-you'll play a key role, collaborating with leading tech professionals to strengthen and protect our economic, financial and payments systems. We dedicate more than $1 billion to technology each year to support the Federal Reserve and our economy, and we're building a dynamic and diverse team for our future.
Bring your passion and expertise, and we'll provide the opportunities that will challenge you and propel your growth-along with a wide range of benefits and perks that support your health, wealth, and life. In addition to competitive compensation, we offer a comprehensive benefits package that includes tuition assistance, generous paid time off, top-notch health care benefits, child and family care leave, professional development opportunities, a 401(k) match, on, and more. All brought together in a flexible work environment where you can truly find balance.
What You Will Do:
Develop conceptual, logical and physical IT engineering designs, that support the infrastructure requirements of varying levels of technical and business application projects.
Analyze our requirements, as it relates to technical infrastructure design, and ensure traceability of the design to our requirements. Assess testing requirements and prepare testing strategies and prepare implementation and transition plans.
Attend and participate in agile ceremonies supporting EUS and Digital Workplace priorities.
Support product owner in assessing backlog, capacity and completing work assignments.
Representing End User Services (EUS) and Digital Workplace area(s) well and interacting with stakeholders and customers in a professional and consistent manner.
Ensure assigned tasks are completed, JIRA cards are updated, and timesheets are submitted in a timely manner.
Perform resolution of complex hardware, environmental software operating systems and subsystems.
Oversee problem avoidance actions.
Analyze and revise existing system logic and documentation.
May authorize risk level changes and recommend solutions to minimize and prevent system interruption.
Recommend and select new software/hardware.
Perform change and problem management using standard tools.
Ensure conformance and compliance with existing system standards.
Measure performance to ensure operation.
Lead technical/complex projects using FRIT/System staff and resources.
Follow and ensure adherence to technical standards for programming and design techniques.
Train System technical staff on use of software/hardware tools following required standards and procedures.
Monitor compliance with internal audit requirements and Information Security Manual guidelines.
What You Have:
Familiar with Microsoft 365 security products and services:
Data Loss Prevention
Information Rights Management
Microsoft Defender for Office 365
Privileged Identity Management
Entra ID
Experience with Microsoft Purview features:
Information Protection
Records Management
Insider Risk Management
Data Lifecycle Management
Sensitive Information Types
Trainable Classifiers
Administrative Units
Comprehensive knowledge about concepts and principles in functional area.
General knowledge of department/business lines, Reserve Banks, and System operations, policies, procedures and technologies.
Excellent interpersonal, negotiation, creativity, attention to detail, and oral and written communications skills tailored for the intended audience.
You are responsible for understanding and applying risk management discipline in decision-making and contributing to your function's risk management.
Work under the direction and guidance in planning details of procedures and methods to attain definite goals.
Makes decisions within established or widely accepted standards.
Achieve assigned/planned results by decisions and actions based on professional methods, training, business principles, and practical experience.
Education and Experience
Bachelor's Degree or equivalent experience with a minimum of 6 years of relevant work experience.
Other Requirements:
Working Conditions:
Will require the use of standard office equipment such as computers, phones, photocopiers.
Physical Demands:
Requires some degree of sitting (for prolonged periods of time), standing, lifting carrying, pushing, pulling more than 20 lbs.
Hours of Work: May require extended work hours.
Occasional travel including overnight stays may be necessary.
May be subject to on-call and call back as needed. May work with moderate noise from equipment.
This posting is a dual grade job posting. Candidates who have a slightly lower level of experience, education, or qualifications may also be considered.
The salary grade for this position is: 15/16. Final salary and offer will be determined by the applicant's background, experience and skills, as well as internal equity and alignment with market data.
We offer a great benefits package that features:
Medical (4 options), Prescription, Dental (3 options), and Vision Insurance with no waiting period
401k/Thrift Plan with generous employer match
Employer-funded Pension Plan
Paid Vacation/Sick Time & Holidays
Monthly $200 Commuter Allowance
Flexible Spending Accounts and Healthcare Spending Accounts
Flexible Work Schedule available in most departments
Life Insurance and Long-Term Disability Insurance
Tuition Reimbursement (undergraduate and graduate)
Parental Leave
Free onsite 24/7 Fitness Center including training classes, Peloton bikes and locker room / shower facilities
Onsite Cafeteria & Coffee Shop
Additional Convenience Benefits, Discounts and More…
Additional Information:
The Federal Reserve Bank of Philadelphia takes your information privacy seriously. Federal Reserve Bank of Philadelphia staff will only email you from the “@phil.frb.org” domain or through the Workday system “****************”. If you are initially contacted by phone, feel free to request that the caller provide you with their email address to validate their identity. If you have any questions about the validity of someone who contacts you regarding this position, please email the Talent Acquisition team at ******************************.
We are an equal opportunity employer committed to hiring the best candidates and to providing equal employment opportunity to all persons without regard to race, color, religion, sex, pregnancy, national origin, age, genetic information, disability, military service, or any other basis protected by law.
We will ensure that individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job responsibilities, and to receive other benefits and privileges of employment. If you need assistance or an accommodation due to a disability, please email us at ******************************.
All Federal Reserve Bank of Philadelphia employees must comply with the Bank's ethics rules, which generally prohibit employees, their spouses/domestic partners, and minor children from owning securities, such as stock, of banks or savings associations or their affiliates, such as bank holding companies and savings and loan holding companies. If you or your spouse/domestic partner or minor child own such securities and would not be willing or able to divest them if you accepted an offer of Bank employment, you should raise this issue with the Recruiter for this posting, who can provide you contact information for our ethics officer if necessary. You should review the Bank's Employee Code of Conduct to ensure compliance with conflict-of-interest rules and personal investment restrictions.
Background investigations and drug testing are required for all new hires as a condition of employment, after the job offer is made. Candidates for positions deemed as "safety sensitive" will also be screened for the presence of marijuana. Employment may not begin until the Bank accepts the results of the background investigation.
Due to the nature of the information, you will have access to, we require that you also complete a more in-depth enhanced background screening (Peraton high).
All employees will be subject to FBI fingerprint / criminal background and Patriot Act/ Office of Foreign Assets Control (OFAC) watch list checks at least once every five years.
Certain eligibility rules apply. You will provide work authorization to prove your eligibility to work in the United States.
This position requires access to confidential supervisory information and/or FOMC information, which is limited to "Protected Individuals" as defined in the U.S. federal immigration law. Protected Individuals include, but are not limited to, U.S. citizens, U.S. nationals, and U.S. permanent residents who either are not yet eligible to apply for naturalization or who have applied for naturalization within the requisite timeframe. Candidates who are permanent residents must sign a declaration of intent to become a U.S. citizen when eligible to do so and pursue a path to citizenship. Candidates who are not U.S. citizens or U.S. permanent residents may be eligible for the information access required for this position if they sign a declaration of intent to become a permanent resident and a U.S. citizen and meet other eligibility requirements. In addition, all candidates must undergo an applicable background check and comply with all applicable information handling rules.
The above statements are intended to describe the general nature, level of work and the requirements of this position. They are not intended to be an exhaustive list of all responsibilities associated with this position or the personnel so classified. While this is intended to be an accurate reflection of this position, management reserves the right to revise this or any job description at its discretion at any time.
Employee will work full-time on site. By applying to this position, you agree you will be available to work on-site in a full-time capacity.
Learn more about the Philly Fed and its culture. Learn more about working for the Philly Fed.
Full Time / Part TimeFull time Regular / TemporaryRegularJob Exempt (Yes / No) YesJob CategoryInformation Technology Family GroupWork ShiftFirst (United States of America)
The Federal Reserve Banks are committed to equal employment opportunity for employees and job applicants in compliance with applicable law and to an environment where employees are valued for their differences.
Always verify and apply to jobs on Federal Reserve System Careers (************************************* or through verified Federal Reserve Bank social media channels.
Privacy Notice
Auto-ApplyCyber Security Analyst
Security engineer job in Media, PA
As the Cyber Security Analyst, you will design and implement IT security policies and systems to protect the organization's computer networks from cyber-attacks. You will also help develop organization-wide best practices for IT security, including security training for staff. You will monitor computer networks for security issues, install security software, and document all security issues or breaches you find. You will report vulnerabilities to management as identified and in a timely manner and ensure remediation.
Essential Duties
Under the general direction of the CIO, the Cyber Security Analyst will:
* Create countywide cybersecurity policies for approval and implementation.
* Perform daily monitoring and support of all systems and networks to identify security issues.
* Investigate security breaches and other cybersecurity incidents.
* Install security measures and operate software to protect systems and information infrastructure, including firewalls, IDS/IPS, and other security systems.
* Document security breaches and assess the damage they cause.
* Work with the IT team to perform tests and uncover network vulnerabilities.
* Fix detected vulnerabilities to maintain a high-security standard.
* Stay current on IT security trends and news.
* Recommend changes to company policies to advance best practices for IT security.
* Perform vulnerability scanning and penetration testing.
* Help colleagues install security software and understand information security management.
* Participate in disaster recovery testing.
* Work cross-functionally as needed to improve the security posture of the organization, including SQA and development team resources.
* Coordinate the collection of security controls evidence in support of certification and customer audits; participate in audits as needed.
* Assist with completion of security questionnaires for customers, partners, and RFP responses.
Qualifications
* 3 years of experience working with Windows operating systems.
* 3 years of experience working with cloud services from a security perspective.
* 5 years of experience working with networking equipment, including switches, routers, firewalls, proxy servers, VPNs, and IDS/IPS.
* Detailed knowledge of network troubleshooting tools such as Fiddler, Wireshark, and Traceroute.
* 3 years of experience working with identity and access authorization systems such as Active Directory, LDAP, and Radius.
* Strong working knowledge of encryption protocols, ciphers, and the configuration of systems.
* Knowledge of current computer security practices and network protocols.
* Experience with Nexpose, Metasploit, or similar security software.
* Customer service-focused and detail-oriented.
* Ability to work effectively as an individual contributor and collaboratively in workgroups.
Physical Requirements
While performing the duties of this position, the employee is frequently required to read documents in paper and electronic form, sit, walk, and talk or hear. Occasionally, the employee will need to stand and climb stairs; reach above shoulder height; and kneel, stoop, crouch, or squat. On rare occasions, the employee will need to lift or carry items.
Work Environment
* 8:30 a.m. to 5:00 p.m. 40 weekly hours.
* Extended hours may be required to meet agency needs.
Contact
To
Cyber Security Analyst
Security engineer job in Wilmington, DE
Details:
Stefanini Group is hiring!
Exciting opportunity awaits, let us help you get started!
Click Apply now or you may call: **************/ email: Deepak Tyagi (**************************) for faster processing!
Job Description:
The Cyber Monitoring Analyst will be part of the Cyber Operations team that is responsible for monitoring and investigating alerts to identify potential incidents. The individual will be required to work closely with other members of the Cyber Operations team to ensure the successful delivery of the alert monitoring, triage, and escalation. Specifically, the Cyber
Monitoring Associate will have the following key responsibilities:
Perform real-time analysis and correlation of logs/alerts.
Follow detailed operational procedures to appropriately analyze, escalate, and assist in remediation of security events.
Utilize multiple security technologies to investigate and analyses alerts.
Deliver timely and detailed documentation related to any incident including the findings, review, and follow-up activities
Participate in the creation, modification and maintenance of all Cyber Monitoring policies and procedures
Keep abreast of cyber security trends and the emerging threat landscape in general
Details:
What the ideal candidate looks like:
1-4 years of experience in IT, IT Security, Security, Technical helpdesk, Security Operations are preferred
Understanding various Cloud technologies such as Azure, AWS, GCP is highly desirable
Also desirable is if they have performed investigation of high severity threats, in on-Prem technologies or in cloud
Strong oral and written communication skills including the ability to interact directly with individuals that do not have an IT background.
Intermediate knowledge of endpoint and network security concepts and tools preferred.
Knowledge of ServiceNow.
Crowdstrike, highly desired.
Experience with event monitoring and security reporting
Ability to exercise sound technical, interpersonal, and organizational judgment while evaluating and solving complex problems.
*Listed salary ranges may vary based on experience, qualifications, and local market. Also, some positions may include bonuses or other incentives*
About Stefanini Group
The Stefanini Group is a global provider of offshore, onshore and near shore outsourcing, IT digital consulting, systems integration, application and strategic staffing services to Fortune 1000 enterprises around the world. Our presence is in countries like Americas, Europe, Africa and Asia, and more than 400 clients across a broad spectrum of markets, including financial services, manufacturing, telecommunications, chemical services, technology, public sector, and utilities. Stefanini is a CMM level 5, IT consulting, company with global presence. We are CMM Level 5 company.
#LI-DT1
#LI-HYBRID
Easy ApplyJr. Information Security Analyst (Controls Testing)
Security engineer job in Malvern, PA
At Customers Bank, we believe in working hard, working smart, working together to deliver memorable customer experiences and having fun. Our vision, mission, and values guide us along our path to achieve excellence. Passion, attitude, creativity, integrity, alignment, and execution are cornerstones of our behaviors. They define who we are as an organization and as individuals. Everyone is encouraged to have personal development plans. By doing so, our team members are on their way to achieve their highest potential and be successful in their personal and professional lives.
This role is required to be ONSITE in Malvern, PA Monday through Thursday with Friday remote.
Must be eligible to work in the U.S. without requiring sponsorship now or in the future.
Who is Customers Bank?
Founded in 2009, Customers Bank is a super-community bank with over $22 billion in assets. We believe in dedicated personal service for the businesses, professionals, individuals, and families we work with.
We get you further, faster.
Focused on you: We provide every customer with a single point of contact. A dedicated team member who's committed to meeting your needs today and tomorrow.
On the leading edge: We're innovating with the latest tools and technology so we can react to market conditions quicker and help you get ahead.
Proven reliability: We always ground our innovation in our deep experience and strong financial foundation, so we're a partner you can trust.
What you'll do:
* Control Testing & Evaluation: Assist in definition of and execute testing procedures to assess the design and effectiveness of key internal controls across business units, technology, and operational processes.
* Risk & Compliance Alignment: Ensure testing activities are aligned with regulatory standards (SOX, FFIEC, FDIC, etc.) and internal policies.
* Issue Identification & Reporting: Document test results, identify control deficiencies, and provide clear recommendations for remediation.
* Collaboration: Work closely with business process owners, auditors, compliance, and risk teams to ensure timely resolution of identified issues.
* Process Improvement: Recommend enhancements to testing methodologies, control design, and risk management practices to strengthen the bank's control environment. Maintain awareness of industry regulatory environment and threat landscape.
* Documentation & Communication: Prepare executive-ready reports, dashboards, and presentations for senior management and regulators, and information technology peers.
* Continuous Monitoring: Participate in ongoing monitoring and follow-up activities to confirm remediation effectiveness and sustainability.
What do you need?
* Must-Haves
* 3+ years of experience in internal audit, compliance testing, risk management, or internal controls.
* Strong knowledge of information security and IT risk control frameworks (e.g., COSO, COBIT, NIST).
* Understanding of financial, operational, and IT control environments.
* Strong analytical skills with attention to detail and accuracy.
* Excellent written and verbal communication skills with the ability to present complex findings clearly.
* Bachelor's degree in information systems, or related field.
* Key Skills
* Risk and control assessments in highly regulated environments
* Understanding of information technology infrastructure (networking, Active Directory, backups, etc.)
* Process analysis and documentation.
* Strong interpersonal skills to work across departments.
* Proficiency with Microsoft Office applications (Excel, Word, PowerPoint).
* Develop and maintain working relationships with audit, GRC, and IT teams to promote continuous control awareness and improvements.
* Nice-to-Haves
* Professional certifications such as CIA, CISSP, CISA, Microsoft certifications, or CRMA.
* Experience with GRC (Governance, Risk, and Compliance) tools.
* Banking or financial services industry experience
Customers Bank is an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.
We also provide "reasonable accommodations", upon request, to qualified individuals with disabilities, in accordance with the Americans with Disabilities Act and applicable state and local laws.
Diversity Statement:
At Customers Bank, we believe in working smart, working together, and having fun while delivering innovative solutions and memorable experiences for our customers. We are committed to the continual advancement of a culture which reflects the value we place on diversity, equity, and inclusion. We honor the diverse experiences, perspectives, and identities of our team members, and we recognize that it is their passion, creativity, and integrity that drives our success. Step into your future with us! Let's take on tomorrow.
Auto-ApplyInformation Security Analyst
Security engineer job in Philadelphia, PA
About the Role: The Network Security Engineer will design, implement, and manage secure network infrastructure to ensure uninterrupted business operations.
Responsibilities:
Configure and maintain firewalls, VPNs, and IDS/IPS systems.
Perform network security monitoring and incident response.
Conduct penetration testing and simulate attacks to identify weaknesses.
Harden routers, switches, and network devices.
Optimize performance without compromising security.
Requirements:
3+ years experience in network engineering/security.
Strong knowledge of Cisco, Palo Alto, or Fortinet firewalls.
Experience with network protocols (TCP/IP, DNS, SSL, VPN).
CCNA Security, CCNP Security, or equivalent certifications.
Required Skills:
Information Security Security
Information Security Specialist (US)
Security engineer job in Mount Laurel, NJ
Charlotte, North Carolina, United States of America **Hours:** 40 **Pay Details:** $87,000 - $151,000 USD TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
**Line of Business:**
Technology Solutions
**Job Description:**
The Information Security Specialist defines, develops and/or implements Technology Controls / Information Security related policies, programs, tools and provides specialized expertise and guidance on assessing risks, identifying potential gaps and providing security solutions to mitigate risks and protect the Bank. Participates on projects of moderate to high complexity and provides complex reporting, analysis, and assessments at the functional, business line or enterprise level for own area.
**Depth & Scope:**
+ Participates on complex, comprehensive or large projects and initiatives
+ Acts as a lead expert resource in technology controls / information security for project teams, the business / organization and/or outside vendors
+ Has advanced knowledge of organization, technology controls / security/ risk issues
**Education & Experience:**
+ Bachelor's degree preferred
+ Information security certification / accreditation an asset
+ 7+ years of relevant experience
+ Expert knowledge of IT security and risk disciplines and practices
**Preferred Qualifications:**
+ Bachelor's degree in Cybersecurity, Information Security, Computer Science, or related field
+ Advanced security certifications (CISSP, CISM, CRISC, or equivalent)
+ 7+ years of experience in information security or cybersecurity
+ 3+ years of experience in security operations or incident response
+ Demonstrated experience with physical security systems and protocols
**Technical Skills:**
+ Strong knowledge of cybersecurity frameworks (NIST, ISO 27001, etc.)
+ Proficiency in security incident and event management (SIEM) tools
+ Understanding of physical security concepts and controls
+ Understanding of digital forensics and e-Discovery processes
+ Strong familiarity with threat intelligence platforms and tools
**Management & Leadership:**
+ Strong experience in risk assessments and methods
+ Proven leadership and management in a technical domain.
+ Proven ability to manage cross-functional teams
+ Experience in developing and implementing security policies
+ Strong organization and project management skills
**Global Business Acumen:**
+ Experience working with international teams
+ Understanding of regional security compliance requirements
+ Knowledge of global security trends and threats
+ Awareness of processes for 24/7 global operational environments
**Soft Skills:**
+ Excellent communication and presentation skills
+ Strong analytical and problem-solving abilities
+ Ability to work under pressure in crisis situations
+ Strategic thinking and decision-making capabilities
+ Strong stakeholder management skills
**Industry Knowledge:**
+ Understanding of enterprise security operations, including SOC design and management, security infrastructure and architecture, continuous monitoring and detection, and incident response procedures
+ Knowledge of incident management frameworks covering NIST Cybersecurity Framework, SANS IR methodologies, MITRE ATT&CK Framework implementation, and incident classification and triage
+ Familiarity with threat intelligence methodologies including threat data collection and analysis, intelligence source evaluation, threat actor attribution, and strategic intelligence reporting
+ Experience with security awareness programs encompassing program development, training material creation, phishing simulation campaigns, and security culture development
**Physical Security Expertise (North America):**
+ Experience in physical security incident management for both Canadian and US operations
+ Proficiency with video surveillance systems and monitoring protocols
+ Knowledge of global physical security policies and compliance frameworks
+ Demonstrated ability to ensure policy adherence across multiple jurisdictions
**Enterprise Fusion & Threat Management:**
+ Awareness of operating models for overseeing enterprise-wide security incident
+ Awareness and understanding of threat intelligence gathering and analysis processes
+ Knowledge of cyber threat detection and attack surface reduction
+ Understanding of cybercrime investigation and prevention
**DDigital Forensics & Strategic Operations:**
+ Awareness of processes, procedures, and controls for providing technical investigative support across multiple business units (HR, Legal, AML, Fraud)
+ Facility management experience in fusion center environments
+ Strong background in fusion center communications and event management
**Physical Requirements:**
Never: 0%; Occasional: 1-33%; Frequent: 34-66%; Continuous: 67-100%
+ Domestic Travel - Occasional
+ International Travel - Occasional
+ Performing sedentary work - Continuous
+ Performing multiple tasks - Continuous
+ Operating standard office equipment - Continuous
+ Responding quickly to sounds - Occasional
+ Sitting - Continuous
+ Standing - Occasional
+ Walking - Occasional
+ Moving safely in confined spaces - Occasional
+ Lifting/Carrying (under 25 lbs.) - Occasional
+ Lifting/Carrying (over 25 lbs.) - Never
+ Squatting - Occasional
+ Bending - Occasional
+ Kneeling - Never
+ Crawling - Never
+ Climbing - Never
+ Reaching overhead - Never
+ Reaching forward - Occasional
+ Pushing - Never
+ Pulling - Never
+ Twisting - Never
+ Concentrating for long periods of time - Continuous
+ Applying common sense to deal with problems involving standardized situations - Continuous
+ Reading, writing and comprehending instructions - Continuous
+ Adding, subtracting, multiplying and dividing - Continuous
**Who We Are:**
TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues.
TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you've got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we're here to support you towards your goals. As an organization, we keep growing - and so will you.
**Our Total Rewards Package**
Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical and mental well-being goals. Total Rewards at TD includes base salary and variable compensation/incentive awards (e.g., eligibility for cash and/or equity incentive awards, generally through participation in an incentive plan) and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off (including Vacation PTO, Flex PTO, and Holiday PTO), banking benefits and discounts, career development, and reward and recognition. Learn more (***************************************
**Additional Information:**
We're delighted that you're considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we're committed to providing the support our colleagues need to thrive both at work and at home.
**Colleague Development**
If you're interested in a specific career path or are looking to build certain skills, we want to help you succeed. You'll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD - and we're committed to helping you identify opportunities that support your goals.
**Training & Onboarding**
We will provide training and onboarding sessions to ensure that you've got everything you need to succeed in your new role.
**Interview Process**
We'll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.
**Accommodation**
TD Bank is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, status as a protected veteran or any other characteristic protected under applicable federal, state, or local law.
If you are an applicant with a disability and need accommodations to complete the application process, please email TD Bank US Workplace Accommodations Program at *************** . Include your full name, best way to reach you and the accommodation needed to assist you with the applicant process.
Federal law prohibits job discrimination based on race, color, sex, sexual orientation, gender identity, national origin, religion, age, equal pay, disability and genetic information.
Information Security Systems Engineer-Ss
Security engineer job in Philadelphia, PA
McLaughlin Research has several openings (pending award) for Information Systems Security Engineers at the Naval Surface Warfare Center, Philadelphia Division.
The Information System Security Engineer (ISSE) designs, develops, implements, and integrates advanced cybersecurity solutions to protect the organization's information systems and data assets. The ISSE III functions as a technical subject matter expert, applying security engineering principles across the system development lifecycle to identify vulnerabilities, mitigate risks, and maintain compliance with information assurance standards. This position often works with classified systems and complex networking environments.
Requirements
Key Responsibilities
Security Architecture and Design: Designing and implementing security architectures for various environments and ensuring trusted relationships between systems.
Risk Management and Compliance: Assessing and mitigating threats, leading the creation of security artifacts like SSPs and RARs, supporting system accreditation under frameworks like RMF, and ensuring compliance with policies such as DoD and NIST SP 800-series.
Vulnerability Management and Incident Response: Conducting vulnerability assessments and ethical hacking, performing risk assessments, leading incident response, and managing automated scanning tools like ACAS and SCAP.
Mentorship and Team Leadership: Guiding junior engineers and analysts and leading teams to achieve security goals.
Cross-Functional Collaboration: Representing security engineering on technical teams and interfacing with stakeholders to translate requirements.
Required Qualifications
Education: BS in Computer Science or relevant field.
Experience: 3-10 years in information security engineering, with specific experience potentially needed for DoD or SAP environments.
Certifications: Must meet DoD 8570/8140 compliance (IASAE Level III, IAT Level III, or IAM Level III) and hold certifications such as CISSP, CASP+, CISM, CSSLP, or CISSP-ISSEP.
Technical Skills: Expertise in RMF, NIST SP 800-53, DISA STIGs/SRGs, experience with security tools (e.g., eMASS, ACAS, Splunk), and knowledge of operating systems and networks (Windows, Linux, Cisco). Scripting proficiency is beneficial.
Security Clearance: U.S. citizenship and eligibility to obtain an active security clearance.
Equal Employment Opportunity Statement:
McLaughlin Research Corporation is an Equal Opportunity and Affirmative Action Employer. It is our policy to recruit, hire, promote, and train for all positions without regard to age, race, creed, religion, national origin, gender identity, marital status, sexual orientation, family responsibilities, pregnancy, minorities, genetic information, status as a person with a disability, amnesty or status as a protected veteran, and to base all such decisions upon the individual's qualifications and ability to perform the work assigned, consistent with contractual requirements and all federal, state and, local laws.
EEO is the Law:
Applicants and employees are protected under Federal law from discrimination.
Information Systems Security Engineer II (ISSE II)
Security engineer job in Philadelphia, PA
Job Description
Dynamic Solutions Technology, LLC, a premier strategic services firm that meets IT and Service needs for commercial and government clients, is seeking a full-time Information Systems Security Engineer II (ISSE II). This position is an exempt role that will provide on-site support at the government customer's area of operation in the Philadelphia, PA location.
--------------------------------------- ACTIVE SECRET CLEARANCE REQUIRED ------------------------------
RESPONSIBILIES
Assist with the developing, maintaining, and tracking Risk Management Framework (RMF) system security plans, which include System Categorization Forms, Platform Information Technology (PIT) Determination
Privacy Impact Assessments (PIA), and Plans of Action and Milestones (POA&M).
Execute the RMF process in support of obtaining and maintaining Interim Authority to Test (IATT), AO approval, Authorization to Operate (ATO), and Denial of Authorization to Operate (DATO).
Identify and tailor IT and Cyber Security (CS) control baselines based on RMF guidelines and categorization of the RMF boundary.
Perform Ports, Protocols, and Services Management (PPSM).
Perform IT and CS vulnerability-level risk assessments.
Execute security control testing as required by a risk assessment or annual security review (ASR).
Mitigate and remediate IT and CS system level vulnerabilities for all assets within the boundary per STIG requirements.
Develop and maintain Plans of Actions and Milestones (POA&M) in Enterprise Mission Assurance Support Service (eMASS).
Develop and maintain system level IT and CS policies and procedures for respective RMF boundaries in accordance with guidance provided by the command ISSMs.
Perform and develop vulnerability assessments with automated tools such as Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP) Compliance Check (SCC) and Evaluate STIG.
Deploy security updates to Information System components.
Perform routine audits of IT system hardware and software components.
Participate in IT change control and configuration management processes.
Upload vulnerability data in Vulnerability Remediation Asset Manager (VRAM).
Image or re-image assets that are part of the assigned RMF boundary.
Install software and troubleshoot software issues as necessary to support compliance of the RMF boundaries' assets.
Assist with removal of Solid-State Drive (SSD), Hard Disk Drive (HDD) or other critical components of assets before destruction and removal from the RMF boundary.
Support configuration change documentation and control processes and maintaining DOD STIG Compliance.
Support cyber compliance of assets that are part of an enterprise IT network to include Windows server and CISCO networking hardware; This includes assessing vulnerabilities, patching and meeting requirements of the STIG for the hardware.
Report compliance issues of network hardware to management to avoid operational loss of the network.
EXPERIENCE AND EDUCATION REQUIREMENTS:
Secret security clearance required
Bachelor's degree in computer science, information technology, or an equivalent STEM l degree from an accredited college or university.
Minimum three (3) years professional relevant experience
Must Meet DoD IAT-II level Certification Requirements: At a minimum one (1) of the following certifications: CCNA-Security, CySA+, GICSP, GSEC, Security+/CE, CND, GCIH, SSCP
Jr. Information Security Analyst (Controls Testing)
Security engineer job in Malvern, PA
At Customers Bank, we believe in working hard, working smart, working together to deliver memorable customer experiences and having fun. Our vision, mission, and values guide us along our path to achieve excellence. Passion, attitude, creativity, integrity, alignment, and execution are cornerstones of our behaviors. They define who we are as an organization and as individuals. Everyone is encouraged to have personal development plans. By doing so, our team members are on their way to achieve their highest potential and be successful in their personal and professional lives.
This role is required to be ONSITE in Malvern, PA Monday through Thursday with Friday remote.
Must be eligible to work in the U.S. without requiring sponsorship now or in the future.
Who is Customers Bank?
Founded in 2009, Customers Bank is a super-community bank with over $22 billion in assets. We believe in dedicated personal service for the businesses, professionals, individuals, and families we work with.
We get you further, faster.
Focused on you: We provide every customer with a single point of contact. A dedicated team member who's committed to meeting your needs today and tomorrow.
On the leading edge: We're innovating with the latest tools and technology so we can react to market conditions quicker and help you get ahead.
Proven reliability: We always ground our innovation in our deep experience and strong financial foundation, so we're a partner you can trust.
What you'll do:
Control Testing & Evaluation: Assist in definition of and execute testing procedures to assess the design and effectiveness of key internal controls across business units, technology, and operational processes.
Risk & Compliance Alignment: Ensure testing activities are aligned with regulatory standards (SOX, FFIEC, FDIC, etc.) and internal policies.
Issue Identification & Reporting: Document test results, identify control deficiencies, and provide clear recommendations for remediation.
Collaboration: Work closely with business process owners, auditors, compliance, and risk teams to ensure timely resolution of identified issues.
Process Improvement: Recommend enhancements to testing methodologies, control design, and risk management practices to strengthen the bank's control environment. Maintain awareness of industry regulatory environment and threat landscape.
Documentation & Communication: Prepare executive-ready reports, dashboards, and presentations for senior management and regulators, and information technology peers.
Continuous Monitoring: Participate in ongoing monitoring and follow-up activities to confirm remediation effectiveness and sustainability.
What do you need?
Must-Haves
3+ years of experience in internal audit, compliance testing, risk management, or internal controls.
Strong knowledge of information security and IT risk control frameworks (e.g., COSO, COBIT, NIST).
Understanding of financial, operational, and IT control environments.
Strong analytical skills with attention to detail and accuracy.
Excellent written and verbal communication skills with the ability to present complex findings clearly.
Bachelor's degree in information systems, or related field.
Key Skills
Risk and control assessments in highly regulated environments
Understanding of information technology infrastructure (networking, Active Directory, backups, etc.)
Process analysis and documentation.
Strong interpersonal skills to work across departments.
Proficiency with Microsoft Office applications (Excel, Word, PowerPoint).
Develop and maintain working relationships with audit, GRC, and IT teams to promote continuous control awareness and improvements.
Nice-to-Haves
Professional certifications such as CIA, CISSP, CISA, Microsoft certifications, or CRMA.
Experience with GRC (Governance, Risk, and Compliance) tools.
Banking or financial services industry experience
Customers Bank is an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.
We also provide “reasonable accommodations”, upon request, to qualified individuals with disabilities, in accordance with the Americans with Disabilities Act and applicable state and local laws.
Diversity Statement:
At Customers Bank, we believe in working smart, working together, and having fun while delivering innovative solutions and memorable experiences for our customers. We are committed to the continual advancement of a culture which reflects the value we place on diversity, equity, and inclusion. We honor the diverse experiences, perspectives, and identities of our team members, and we recognize that it is their passion, creativity, and integrity that drives our success. Step into your future with us! Let's take on tomorrow.
Auto-ApplyInformation Security Specialist (US) - GRC
Security engineer job in Mount Laurel, NJ
Hours: 40 Pay Details: $87,000 - $151,000 USD TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
Line of Business:
Technology Solutions
Job Description:
The Information Security Specialist defines, develops and/or implements Technology Controls / Information Security related policies, programs, tools and provides specialized expertise and guidance on assessing risks, identifying potential gaps and providing security solutions to mitigate risks and protect the Bank. Participates on projects of moderate to high complexity and provides complex reporting, analysis, and assessments at the functional, business line or enterprise level for own area.
Depth & Scope:
* Participates on complex, comprehensive or large projects and initiatives
* Acts as a lead expert resource in technology controls / information security for project teams, the business / organization and/or outside vendors
* Has advanced knowledge of organization, technology controls / security/ risk issues
Education & Experience:
* Bachelor's degree preferred
* Information security certification / accreditation an asset
* 7+ years of relevant experience
* Expert knowledge of IT security and risk disciplines and practices
Preferred Qualifications:
* Experience leading assessments of audit and regulatory remediation plans, providing guidance on IT risk governance and compliance frameworks, developing governance oversight practices, identifying emerging risk themes, and leading continuous improvement projects using agile and AI technologies
* Expert knowledge of IT audit and control methodologies, project and change management skills, competencies in technology controls and emerging threats, and proficiency in Agile frameworks and AI-driven solution development
* 7 years of IT risk experience, preferably in regulated industries and financial services, with knowledge of IT governance frameworks like ITIL, NIST, and COBIT.
* Certifications such as CRISC, CISA, and optionally CISSP
Physical Requirements:
Never: 0%; Occasional: 1-33%; Frequent: 34-66%; Continuous: 67-100%
* Domestic Travel - Occasional
* International Travel - Never
* Performing sedentary work - Continuous
* Performing multiple tasks - Continuous
* Operating standard office equipment - Continuous
* Responding quickly to sounds - Occasional
* Sitting - Continuous
* Standing - Occasional
* Walking - Occasional
* Moving safely in confined spaces - Occasional
* Lifting/Carrying (under 25 lbs.) - Occasional
* Lifting/Carrying (over 25 lbs.) - Never
* Squatting - Occasional
* Bending - Occasional
* Kneeling - Never
* Crawling - Never
* Climbing - Never
* Reaching overhead - Never
* Reaching forward - Occasional
* Pushing - Never
* Pulling - Never
* Twisting - Never
* Concentrating for long periods of time - Continuous
* Applying common sense to deal with problems involving standardized situations - Continuous
* Reading, writing and comprehending instructions - Continuous
* Adding, subtracting, multiplying and dividing - Continuous
The above statements are intended to describe the general nature and level of work being performed by people assigned to this job. They are not intended to be an exhaustive list of all responsibilities, duties and skills required. The listed or specified responsibilities & duties are considered essential functions for ADA purposes.
Who We Are:
TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues.
TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you've got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we're here to support you towards your goals. As an organization, we keep growing - and so will you.
Our Total Rewards Package
Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical and mental well-being goals. Total Rewards at TD includes base salary and variable compensation/incentive awards (e.g., eligibility for cash and/or equity incentive awards, generally through participation in an incentive plan) and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off (including Vacation PTO, Flex PTO, and Holiday PTO), banking benefits and discounts, career development, and reward and recognition. Learn more
Additional Information:
We're delighted that you're considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we're committed to providing the support our colleagues need to thrive both at work and at home.
Colleague Development
If you're interested in a specific career path or are looking to build certain skills, we want to help you succeed. You'll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD - and we're committed to helping you identify opportunities that support your goals.
Training & Onboarding
We will provide training and onboarding sessions to ensure that you've got everything you need to succeed in your new role.
Interview Process
We'll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.
Accommodation
TD Bank is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, status as a protected veteran or any other characteristic protected under applicable federal, state, or local law.
If you are an applicant with a disability and need accommodations to complete the application process, please email TD Bank US Workplace Accommodations Program at ***************. Include your full name, best way to reach you and the accommodation needed to assist you with the applicant process.
Auto-ApplyInformation Systems Security Engineer III (ISSE III)
Security engineer job in Philadelphia, PA
Dynamic Solutions Technology, LLC, a premier strategic services firm that meets IT and Service needs for commercial and government clients, is seeking a full-time Information Systems Security Engineer III (ISSE III). This position is an exempt role that support will be provided on site in the government customer's area of operation in the Philadelphia, PA location.
----------------------------------------------------- Active Secret Clearance Required --------------------------------------
RESPONSIBILIES
Assist with the developing, maintaining, and tracking Risk Management Framework (RMF) system security plans, which include System Categorization Forms, Platform Information Technology (PIT) Determination
Checklists, Assess Only (AO) Determination Checklists, Implementation Plans, System Level Continuous Monitoring (SLCM) Strategies, System Level Policies, Hardware Lists, Software List, System Diagrams,
Privacy Impact Assessments (PIA), and Plans of Action and Milestones (POA&M).
Execute the RMF process in support of obtaining and maintaining Interim Authority to Test (IATT), AO approval, Authorization to Operate (ATO), and Denial of Authorization to Operate (DATO).
Identify and tailor IT and Cyber Security (CS) control baselines based on RMF guidelines and categorization of the RMF boundary.
Perform Ports, Protocols, and Services Management (PPSM).
Perform IT and CS vulnerability-level risk assessments.
Execute security control testing as required by a risk assessment or annual security review (ASR).
Mitigate and remediate IT and CS system level vulnerabilities for all assets within the boundary per STIG requirements.
Develop and maintain Plans of Actions and Milestones (POA&M) in Enterprise Mission Assurance Support Service (eMASS).
Develop and maintain system level IT and CS policies and procedures for respective RMF boundaries in accordance with guidance provided by the command ISSMs.
Implement and assess STIG and SRGs.
Perform and develop vulnerability assessments with automated tools such as Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP) Compliance Check (SCC) and Evaluate STIG.
Deploy security updates to Information System components.
Perform routine audits of IT system hardware and software components.
Maintain inventory of Information System components.
Participate in IT change control and configuration management processes.
Upload vulnerability data in Vulnerability Remediation Asset Manager (VRAM).
Image or re-image assets that are part of the assigned RMF boundary.
Install software and troubleshoot software issues as necessary to support compliance of the RMF boundaries' assets.
Assist with removal of Solid-State Drive (SSD), Hard Disk Drive (HDD) or other critical components of assets before destruction and removal from the RMF boundary.
Support configuration change documentation and control processes and maintaining DOD STIG Compliance.
Support cyber compliance of assets that are part of an enterprise IT network to include Windows server and CISCO networking hardware; This includes assessing vulnerabilities, patching and meeting requirements of the STIG for the hardware.
Report compliance issues of network hardware to management to avoid operational loss of the network.
EXPERIENCE AND EDUCATION REQUIREMENTS:
Secret security clearance required
Bachelor's degree in computer science, information technology, or an equivalent STEM l degree from an accredited college or university.
Minimum five (5) years professional relevant experience:; or 7 years of professional experiance without bachalors degree
Must Meet DoD IAT-III level Certification Requirements: At a minimum 2-3 of one of the following certifications: CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, CCSP
Experience and Skills:
Excellent oral and written skills.
Excellent critical thinking skills.
Proficient in Microsoft applications such as Word, Excel, PowerPoint, and Outlook.
Ability to work independently and as a team member
Ability to learn and apply technical concepts to assigned duties
Information Security Specialist - Cyber Resilience
Security engineer job in Mount Laurel, NJ
Hours: 40 Pay Details: $87,000 - $151,000 USD TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
Line of Business:
Technology Solutions
Job Description:
The Information Security Specialist defines, develops and/or implements Technology Controls / Information Security related policies, programs, tools and provides specialized expertise and guidance on assessing risks, identifying potential gaps and providing security solutions to mitigate risks and protect the Bank. Participates on projects of moderate to high complexity and provides complex reporting, analysis, and assessments at the functional, business line or enterprise level for own area.
The role involves designing and implementing cyber resilience strategies, leading initiatives to improve organizational preparedness, conducting risk assessments, and collaborating with various teams to align resilience goals with business objectives. Responsibilities also include developing incident response plans, managing continuity strategies, providing expert guidance during incidents, and delivering training programs to foster a culture of resilience.
Depth & Scope:
* Participates on complex, comprehensive or large projects and initiatives
* Acts as a lead expert resource in technology controls / information security for project teams, the business / organization and/or outside vendors
* Has advanced knowledge of organization, technology controls / security/ risk issues
Education & Experience:
* Bachelor's degree preferred
* Information security certification / accreditation an asset
* 7+ years of relevant experience
* Expert knowledge of IT security and risk disciplines and practices
Preferred Qualification :
* Design, develop, and implement comprehensive cyber resilience strategies.
* Lead cross-functional initiatives to enhance organizational preparedness against cyber threats and incidents.
* Conduct risk assessments and business impact analyses to identify vulnerabilities.
* Collaborate with IT, security teams, and business units to align resilience goals with organizational objectives.
* Develop and manage incident response plans, continuity strategies, and recovery protocols.
* Provide expert guidance during cybersecurity incidents, ensuring rapid response and recovery.
Physical Requirements:
Never: 0%; Occasional: 1-33%; Frequent: 34-66%; Continuous: 67-100%
* Domestic Travel - Occasional
* International Travel - Never
* Performing sedentary work - Continuous
* Performing multiple tasks - Continuous
* Operating standard office equipment - Continuous
* Responding quickly to sounds - Occasional
* Sitting - Continuous
* Standing - Occasional
* Walking - Occasional
* Moving safely in confined spaces - Occasional
* Lifting/Carrying (under 25 lbs.) - Occasional
* Lifting/Carrying (over 25 lbs.) - Never
* Squatting - Occasional
* Bending - Occasional
* Kneeling - Never
* Crawling - Never
* Climbing - Never
* Reaching overhead - Never
* Reaching forward - Occasional
* Pushing - Never
* Pulling - Never
* Twisting - Never
* Concentrating for long periods of time - Continuous
* Applying common sense to deal with problems involving standardized situations - Continuous
* Reading, writing and comprehending instructions - Continuous
* Adding, subtracting, multiplying and dividing - Continuous
The above statements are intended to describe the general nature and level of work being performed by people assigned to this job. They are not intended to be an exhaustive list of all responsibilities, duties and skills required. The listed or specified responsibilities & duties are considered essential functions for ADA purposes.
Who We Are:
TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues.
TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you've got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we're here to support you towards your goals. As an organization, we keep growing - and so will you.
Our Total Rewards Package
Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical and mental well-being goals. Total Rewards at TD includes base salary and variable compensation/incentive awards (e.g., eligibility for cash and/or equity incentive awards, generally through participation in an incentive plan) and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off (including Vacation PTO, Flex PTO, and Holiday PTO), banking benefits and discounts, career development, and reward and recognition. Learn more
Additional Information:
We're delighted that you're considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we're committed to providing the support our colleagues need to thrive both at work and at home.
Colleague Development
If you're interested in a specific career path or are looking to build certain skills, we want to help you succeed. You'll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD - and we're committed to helping you identify opportunities that support your goals.
Training & Onboarding
We will provide training and onboarding sessions to ensure that you've got everything you need to succeed in your new role.
Interview Process
We'll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.
Accommodation
TD Bank is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, status as a protected veteran or any other characteristic protected under applicable federal, state, or local law.
If you are an applicant with a disability and need accommodations to complete the application process, please email TD Bank US Workplace Accommodations Program at ***************. Include your full name, best way to reach you and the accommodation needed to assist you with the applicant process.
Auto-ApplyInformation Systems Security Engineer II (ISSE II)
Security engineer job in Philadelphia, PA
Dynamic Solutions Technology, LLC, a premier strategic services firm that meets IT and Service needs for commercial and government clients, is seeking a full-time Information Systems Security Engineer II (ISSE II). This position is an exempt role that will provide on-site support at the government customer's area of operation in the Philadelphia, PA location.
--------------------------------------- ACTIVE SECRET CLEARANCE REQUIRED ------------------------------
RESPONSIBILIES
Assist with the developing, maintaining, and tracking Risk Management Framework (RMF) system security plans, which include System Categorization Forms, Platform Information Technology (PIT) Determination
Privacy Impact Assessments (PIA), and Plans of Action and Milestones (POA&M).
Execute the RMF process in support of obtaining and maintaining Interim Authority to Test (IATT), AO approval, Authorization to Operate (ATO), and Denial of Authorization to Operate (DATO).
Identify and tailor IT and Cyber Security (CS) control baselines based on RMF guidelines and categorization of the RMF boundary.
Perform Ports, Protocols, and Services Management (PPSM).
Perform IT and CS vulnerability-level risk assessments.
Execute security control testing as required by a risk assessment or annual security review (ASR).
Mitigate and remediate IT and CS system level vulnerabilities for all assets within the boundary per STIG requirements.
Develop and maintain Plans of Actions and Milestones (POA&M) in Enterprise Mission Assurance Support Service (eMASS).
Develop and maintain system level IT and CS policies and procedures for respective RMF boundaries in accordance with guidance provided by the command ISSMs.
Perform and develop vulnerability assessments with automated tools such as Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP) Compliance Check (SCC) and Evaluate STIG.
Deploy security updates to Information System components.
Perform routine audits of IT system hardware and software components.
Participate in IT change control and configuration management processes.
Upload vulnerability data in Vulnerability Remediation Asset Manager (VRAM).
Image or re-image assets that are part of the assigned RMF boundary.
Install software and troubleshoot software issues as necessary to support compliance of the RMF boundaries' assets.
Assist with removal of Solid-State Drive (SSD), Hard Disk Drive (HDD) or other critical components of assets before destruction and removal from the RMF boundary.
Support configuration change documentation and control processes and maintaining DOD STIG Compliance.
Support cyber compliance of assets that are part of an enterprise IT network to include Windows server and CISCO networking hardware; This includes assessing vulnerabilities, patching and meeting requirements of the STIG for the hardware.
Report compliance issues of network hardware to management to avoid operational loss of the network.
EXPERIENCE AND EDUCATION REQUIREMENTS:
Secret security clearance required
Bachelor's degree in computer science, information technology, or an equivalent STEM l degree from an accredited college or university.
Minimum three (3) years professional relevant experience
Must Meet DoD IAT-II level Certification Requirements: At a minimum one (1) of the following certifications: CCNA-Security, CySA+, GICSP, GSEC, Security+/CE, CND, GCIH, SSCP